hhhai

hhhai is a security researcher credited with 56 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #107 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 55 findings.

Their research concentrates on Cross-Site Scripting, which accounts for 17 of their findings (30%). Other recurring categories include Missing Authorization, SQL Injection. The average CVSS score across these disclosures is 6.6, peaking at 9.8. Severity breakdown: 2 critical and 25 high.

The most affected software includes WP Job Portal (3), Active Woot Products Tables… (2), EventPrime (2), across 51 distinct plugins, themes and core versions in total.

50 of the 56 disclosed issues have a vendor fix, while 6 remain unpatched. The most severe finding, "WebinarIgnition – Live, Automated & Evergreen Webinar System also for WooCommerce < 4.08.253 - Unauthenticated Privilege Escalation", scores 9.8 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#107

of 3,515 researchers

Vulns

56

Critical2
High25
Medium29
Low0
Affected Assets

51

51plugins
Avg CVSS

6.6

Average score of vulnerabilities

Researcher Submissions

56 records
2026-08-19 00:00CVE-2026-73992
8.8
High
hhhaiYes
2026-08-14 00:00CVE-2026-28567
5.3
Medium
hhhaiNo
2026-08-11 00:00CVE-2026-27537
7.2
High
hhhaiYes
2026-08-05 00:00CVE-2026-66452
5.3
Medium
hhhaiYes
2026-08-04 00:00CVE-2026-28139
8.1
High
hhhaiYes
2026-07-24 00:00CVE-2026-59553
7.2
High
hhhaiYes
2026-07-23 00:00CVE-2026-65510
7.2
High
hhhaiNo
2026-07-22 00:00CVE-2026-59555
9.1
Critical
hhhaiYes
2026-07-20 00:00CVE-2026-57696
8.1
High
hhhaiYes
2026-07-16 00:00CVE-2026-61947
7.2
High
hhhaiYes
Showing 1–10 of 56 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C